Hi Emanuele,
I see there has been no response on here so I wanted to check to see if you saw this blog posted a couple of days ago:
I also wanted to share an update from our Threat Research team, posted yesterday:
The Threat Research Team is actively monitoring this vulnerability. (CVE-2025-55184)
We have deployed a rule on the Cloud WAF based on a publicly shared PoC, but we have not observed any exploitation happening in the wild.This suggests that either the PoC is inaccurate or no one is attempting to exploit this vulnerability.The more probable explanation is that the PoC is not reliable.Therefore, we plan to wait for a more accurate PoC to be released before deciding on our next steps.
I hope this helps!
------------------------------
Sarah Lamont
Digital Community Manager
------------------------------